Expel Quarterly Threat Report Q3 2024, volume IV: Suspicious infrastructure from phishing-as-a-service (PhaaS) platforms
ID: 91ce0426-4675-5e0d-b553-6861f82cb8b0
STIX ID: report--91ce0426-4675-5e0d-b553-6861f82cb8b0
Feed Name: Expel Blog
This Volume IV threat report examines the rise of phishing-as-a-service (PhaaS) driving identity-based incidents in Q3 2024, noting that authentications from hosting/VPS providers (suspicious infrastructure) rose to 51% of identity incidents. The authors identify three recurring PhaaS platforms (Tycoon 2FA, Rockstar/Dadsec, JSNOM), describe observable indicators (phishing email patterns, credential harvester styles, hosting providers), and recommend enriching anomalous-authentication alerts with hosting-provider checks and cross-customer pattern analysis to detect and mitigate these campaigns earlier.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
